[strongSwan] Getting Strongswan to NOT use port 500 ?

2010-02-02 Thread Graham Hudspith
Dear All, We're happily using strongSwan 4.3.5+, but we've come up against a situation where the route between us and the Security-Gateway has a firewall which is configured to open port 4500 only and to NOT open port 500. Is there any way to configure strongSwan to go straight to using port

Re: [strongSwan] a negotiation timeout after IKE_SA_INIT may become unrecoverable

2010-02-02 Thread Martin Willi
Hi Christophe, If an IKEv2 negotiation fails due to a timeout (typically during the IKE_AUTH exchange) after a successful IKE_SA_INIT exchange [...] The SA will remain in a zombie state, even a later acquire message will not enable to leave this lock up situation. I agree, this is a case